logo

Stopping a targeted attack on a Managed Service Provider (MSP) with ThreatDown MDR

ID: 376b75ad-4e6f-58ce-a2b4-6f310c4763d7

STIX ID: report--376b75ad-4e6f-58ce-a2b4-6f310c4763d7

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2024-02-28

Date Updated: 2026-04-28

...
...

In late 2023 ThreatDown MDR discovered and stopped a three-month stealthy malware campaign targeting a European MSP that leveraged living-off-the-land techniques and legitimate remote access/RMM tools (AnyDesk, TeamViewer, ScreenConnect) while attempting to deploy Remcos/AsyncRAT and communicate with known C2 servers; ThreatDown blocked malicious connections, isolated affected endpoints, and recommended re-imaging, password changes, and tighter filtering to remediate the intrusion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.